> Markdown version of [/jobs/ext/2983254-digital-forensics-analyst-sme](https://www.wearedevelopers.com/jobs/ext/2983254-digital-forensics-analyst-sme). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Digital Forensics Analyst SME - **Company:** Booz Allen Hamilton Inc. - **Location:** Bethesda, MD, United States (Remote available) - **Experience:** Experienced - **Salary:** $62,000.0 - $141,000.0 - **Contract:** Internship / Graduate position - **Skills:** Microsoft Windows, Amazon Web Services, Apple Mac Systems, Microsoft Azure, Cyber Security, Computer Forensics, Data Recovery, Linux, Digital Forensics, Reverse Engineering, Security Information and Event Management, Malware, Encase, Splunk - **Published:** September 18, 2026 - **Apply:** https://careers.boozallen.com/jobs/JobDetail?jobId=130573 ## About the Role * 2+ years of experience in a Security Operations Center (SOC) providing forensic analysis, imaging, log and evidence analysis or preservation, chain-of-custody, incident documentation, and coordination with Federal stakeholders * Experience analyzing and responding to forensic security requests across enterprise host including Linux, Windows, or macOS and network-based platforms * Experience developing or contributing to evidence collection, examination, and chain-of-custody documentation or standard operating procedures * Experience using Splunk SIEM platform to support investigations and evidence enrichment * Experience using a forensic recovery of evidence device (FRED) to collect, store, and maintain forensic images * Experience with malware analysis and reverse engineering * Ability to analyze and correlate data from multiple technical sources to identify malicious activity, artifacts, indicators, or investigative leads * Ability to communicate clearly with both technical and non-technical audiences, including the production of high-quality incident reports, briefings, and technical documentation * Public Trust * Bachelor's degree Nice If You Have: * Experience using industry forensic suites and toolsets such as EnCase, FTK, X-Ways, Cellebrite, Autopsy, KAPE, or Velociraptor * Experience performing volatile memory acquisition and analysis * Experience with cloud forensics methodologies such as AWS, Azure, or GCP including log acquisition and artifact preservation * Experience with federal security controls such as NIST 800-53, RMF, or FedRAMP and impact on investigative activities * Ability to build strong client relationships, collaborate across varied teams, and communicate complex technical concepts in a clear, inclusive manner * DFIR Certifications such as GIAC, GCFA, GCFE, GCIH, CFCE, IACIS, and EnCase EnCE Certifications Vetting: Applicants selected will be subject to a government investigation and may need to meet eligibility requirements of the U.S. government client; Public Trust determination is required. ## Description Serve as a key member of a 24x7x365 Security Operations Center and Incident Response team, responsible for conducting evidence collection, forensic analysis, data recovery, and reporting in response to incident investigations. The role performs hands-on digital forensics activities such as forensic imaging, analysis of physical and virtual drives, and incident documentation while leveraging FRED's and forensic tools to capture and preserve evidence for security events. The analyst contributes to the development forensics playbooks and standard operating procedures, conducts ad-hoc forensic analysis, and supports the SOC with investigating security events. This position collaborates closely with federal stakeholders, communicates findings to technical and non-technical audiences, and produces high-quality reports and briefings, all while helping to advance the maturity and effectiveness of the organization's security operations. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Discover the open source trio you didn’t expect: .NET and PostgreSQL on Linux](https://www.wearedevelopers.com/videos/2042-discover-the-open-source-trio-you-didn-t-expect-net-and-postgresql-on-linux) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [How Much FAANG Companies Actually Pay Software Engineers in 2025](https://www.wearedevelopers.com/magazine/230-how-much-faang-companies-actually-pay-software-engineers-in-2025) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany)